MALICIOUS — CRITICAL
reidax[.]com
The domain reidax.com was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently taken offline.
- VirusTotal
- 16/95
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
reidax.com — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcrypto; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain reidax.com was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently taken offline. DNS resolution points to 188.114.96.3, an IP address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative nameservers are elias.ns.cloudflare.com and elisa.ns.cloudflare.com, indicating the use of Cloudflare’s DNS and CDN services. The site presented a page title of "Reidax: Most Popular Online Crypto Casino Based on Blockchain," which aligns with the classified scam type of a crypto casino.
SSL termination is provided by Google Trust Services under the WE1 certificate, offering a valid HTTPS indicator but not mitigating the underlying malicious intent. Malware and phishing detection engines on VirusTotal flagged the domain in 16 of 95 scans, and the domain appears on three security blocklists. It has been actively blocked by PhishDestroy, MetaMask, and SEAL, reflecting coordinated defensive actions. Infrastructure analysis shows the presence of Cloudflare Browser Insights and generic Cloudflare technologies, while the underlying phishing kit has been identified as the Gambler Scam kit, a known template for crypto‑related fraud.
While the site is offline, the observable indicators suggest a high‑risk infrastructure that could be re‑used for future campaigns. Defenders should continue to monitor the IP address 188.114.96.3 for any resurgence, enforce blocklist entries for reidax.com, and consider adding the associated nameservers to DNS‑based threat‑intelligence feeds. Network traffic to the Cloudflare IP should be inspected for suspicious payloads, and any attempts to resolve the domain should be denied. Continuous review of VirusTotal and other sandbox results is recommended to capture any new variants that may emerge from the same infrastructure.
Охват данных12 recorded checks
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | reidax.com |
phishing | Phishing Block |
| Hagezi Threat Feed | reidax.com |
malicious | Sinkholed |
| DNS4EU | reidax.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:17:17 UTC
История жалоб на злоупотребления · 4 stored reports over 9 days · click to expand
-
Report #2 ICANN CC 1556h still active Apr 20, 2026 · 14:31 UTCESCALATION #2 (1556h active): Phishing - reidax[.]comabuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 1610h still active Apr 22, 2026 · 20:15 UTCESCALATION #3 (1610h active): Phishing - reidax[.]comabuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 1703h still active Apr 26, 2026 · 17:15 UTCESCALATION #4 (1703h active): Phishing - reidax[.]comabuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1752h still active Apr 28, 2026 · 18:20 UTCESCALATION #5 (1752h active): Phishing - reidax[.]comabuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
Технологии · 2 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260214-F21BB1 Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.